2026 CVE Vulnerabilities

45,891 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-2522CRITICAL9.8A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is an unknown function of the file /src/mme/...
CVE-2026-2521CRITICAL9.8A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_re...
CVE-2026-26369CRITICAL9.8eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization c...
CVE-2026-26366CRITICAL9.8eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after ...
CVE-2026-1490CRITICAL9.8The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi...
CVE-2026-1306CRITICAL9.8The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension ...
CVE-2026-24853CRITICAL9.8Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the...
CVE-2026-26273CRITICAL9.8Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1....
CVE-2026-26335CRITICAL9.8Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web app...
CVE-2026-26333CRITICAL9.8Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The se...
CVE-2026-26190CRITICAL9.8Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus expose...
CVE-2026-26268CRITICAL9.9Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in ver...
CVE-2026-26221CRITICAL9.8Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workf...
CVE-2026-23112CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu...
CVE-2026-26068CRITICAL9.9emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadat...
CVE-2026-1358CRITICAL9.8Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maxim...
CVE-2026-26011CRITICAL9.8navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulne...
CVE-2026-25996CRITICAL9.8Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li...
CVE-2026-24895CRITICAL9.8FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly han...
CVE-2026-24044CRITICAL9.2Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kuberne...
CVE-2026-26219CRITICAL9.3newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not inco...
CVE-2026-26218CRITICAL9.8newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisi...
CVE-2026-26216CRITICAL10Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl ...
CVE-2026-26214CRITICAL9.1Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HT...
CVE-2026-1729CRITICAL9.8The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. Th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now